Host University
NYU Abu Dhabi

AI Hardware Attack Challenge 2025

Base Competition
Year
2025
Timeline
Items
First challenge given
EST
Second challenge given
EST
All challenges due
EST
Finalists announced
EST
​Final challenge given
EST
Winners announced
EST
Note
Note: The challenges do not need to be completed within the month they are given, this is just when we are releasing them. We will also update a monthly leaderboard in this repository as the competition progresses. All teams will have up until the 1 October deadline to submit their challenges to earn points and be considered as a finalist team.
Challenge Details

Each challenge has its own details for the competition. Those details are given on the GitHub for this competition here.

Challenge 1: The first challenges will focus on leveraging generative AI to add hardware Trojans to an AES core. Three difficulties of challenge will be provided: easy, medium, and hard, with each worth increasing points. Teams can submit all three difficulties of challenge to earn the most points.

Judging Criteria

Each challenge will have its own rubric regarding how points can be awarded. Challenges will have their base functionality automatically graded, and manual judging will take place over the following days to ensure all rules were followed, as well as to award additional points for completing further objectives. These extra points will be awarded for each competition for things like “most creative use of AI”. Please refer to each challenge's rubric for how this will be done.

Each submission must also be fully open source, guidelines for this are here.

Registration Guidelines

Please fill out the registration Google Form to register your team. Teams must consist of:

  • Up to 4 student team members
  • One team advisor/mentor
Resources
Awards
1st
ChipWhisperer Side-Channel and Glitching Starter Pack*
3rd
Space on a future Tiny Tapeout
* Can also request space on Tiny Tapeout, amount of space and PCB quantity must be approximately equal to the original prize cost
Winners
1st
Indian Institute of Technology, Kanpur
Soham Panchal
Ananthan R
Jugal Pahuja
Ramya Rasika S R
2nd
University of New South Wales
Annie Qiu
Danny Tan
Xinzhang Chen
Zhongtai Zhang
3rd
New Mexico State University
Md Omar Faruque
Rensselaer Polytechnic Institute & University of Texas
Samit Shahnawaz Miftah
Amisha Srivastava
Swastik Bimal Bhattacharya
Sanjay Das
Hanpei Liu
Organizers & Judges
Jason Blocklove
Organizer
NYU
Global Student Lead
Jason Blocklove

​Operational Technology Security Competition

Elevate Your Expertise: Announcing the Inaugural OT-Sec Competition!
Description

Prepare to advance your cybersecurity capabilities! We are excited to announce the launch of the in-person Operational Technology (OT) Security Competition during the CSAW event. This pioneering event transcends traditional formats, offering a unique opportunity to engage, learn, and collaborate within a dynamic and intellectually stimulating environment. Participants will have the chance to address authentic OT challenges, partner with peers, and demonstrate their proficiencies in a competitive yet supportive setting.

​Operational Technology Security Competition
Short Name
OT Security Competition

LLM CTF Attack Competition

It’s time to think a little differently about the capabilities of generative AI.
Description

With the rising popularity of large language models (LLMs), the capabilities of new models include identifying software vulnerabilities and generating code to exploit them. Capture the Flag (CTF) events are cybersecurity competitions where players solve challenges to identify vulnerabilities and reveal 'flags' to score points.

Your job in this competition is to use generative autonomous AI to solve CTF challenges. An autonomous framework will follow your prompts and, powered by the LLM, autonomously perform steps to Capture the Flag (i.e. no human interaction!). For this competition, you can either bring your own autonomous framework (a.k.a. agent) to the table, or make feature enhancements to a provided baseline agent. We will offer one baseline agent and provide technical support.

Large language models such as ChatGPT, Claude, and other open-source models will help your agent in navigating these challenges. The LLM CTF Attack Competition challenges will be drawn from previous CTF competitions and will include common categories (pwn, web, rev, forensics, misc.).

A successful submission will include:

  1. All the prompts and responses from the language model – this is typically provided in an agent’s transcripts/trajectories/logs output or your conversation history.
  2. A brief write-up that details of your strategies, any formats are accepted as far as your idea is clearly addressed. That will contribute to your presentation quality points.
LLM CTF Attack Competition Icon

Hack My Robot

Description

The Hack My Robot Challenge aims to raise awareness about the cybersecurity aspects of increasingly digitalized construction environments with a particular focus on robotics. Students who want to learn more about operational technology security, robotics, and construction technologies are invited to attend. The participants will be challenged to come up with ideas to compromise the data and operations of the given robotic system considering the characteristics of construction sites. 

This challenge is organized by the S.M.A.R.T. Construction Research Group with the support and collaboration from the Center for Cybersecurity (CCS) at NYUAD, the Center for Sand Hazards and Opportunities for Resilience, Energy, and Sustainability (SHORES), and the Center for AI and Robotics (CAIR) at NYUAD.

Hack My Robot

Capture the Flag

Description

CSAW CTF is one of the oldest and biggest CTFs with 1216 teams with 1+ points in 2021. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.

CSAW CTF occurs over two rounds: a Qualifying Round in September and a Final Round in November. 

Capture the Flag

BioHack 3D

Can You Fool the Deep-Learning QR-Code Authenticator?
Description

A trusted third party (TTP) uses a DL-based authentication system to decide whether a submitted melt-electrowritten QR code (MEW-QRC) is genuine.

The green route is the legitimate path: an authentic MEW-QRC is captured, submitted, and accepted.

The real question is what happens along the red and orange routes.

Can you manipulate, counterfeit, or strategically alter an MEW-QRC image so convincingly that the authenticator makes the wrong decision?

Your Mission

Think like an attacker. Challenge the AI. Find the weakness.

Your objective is to explore whether a forged or manipulated MEW-QRC can cross the authentication barrier and be incorrectly classified as genuine.

You may investigate how the system responds to:

  • subtle image manipulation and perturbations,
  • counterfeit or reconstructed MEW-QRC patterns,
  • changes in morphology, texture, orientation, or image quality,
  • physical and imaging variations that could confuse the authentication model.

The ultimate goal is simple:

Can you turn an attack route into an accepted authentication?

In other words:

Can you flip the outcome: make the X on the red route a ✓ and the ✓ on the orange path an X, as authenticated by the TTP?

Challenge Description
An illustration of the adversarial framework.

 

BioHACK3D challenges you to combine AI, computer vision, cybersecurity, and creative problem solving to probe the limits of a real physical-authentication problem.

Break the assumption. Challenge the model. Fool the authenticator.

BioHack 3D

Applied Research Competition

Description

This "Best Paper Award" assesses the top scholarly security research from the previous year. The focus of this competition is on research that has a practical impact.  With eligibility limited to already published papers or camera-ready papers, CSAW has a reputation for drawing some of the best security research worldwide. 

Applied Research